4 ms·
How does that works for, say, Chromium or Firefox on Linux ?
by slooonz 2y ago
How does that works for, say, Chromium or Firefox on Linux ?
- rvnx 2y agoI believe the plan was to ask the TPM of the computer. From what I understood, each TPM has a unique private/public key pair (Endorsement Key (EK)), and then this key is certified by the manufacturer of the TPM. From there, you can generate a Attestation Keys, and these keys are signed by the EK. https://security.stackexchange.com/questions/235148/whats-the-difference-between-the-endorsement-key-and-the-attestation-identity-k https://security.stackexchange.com/questions/235148/whats-th... So essentially, at the end of the day, Chromium would ask the TPM for attestation, and it would act as a unique Device ID. Then they can allow only a selected list of TPM manufacturers certificates, to prevent emulators for example. TL;DR: Chromium on Linux would ask the TPM chip for a signature, and each TPM chip has a different signature from the moment it is out of the factory.